Space_Munkey Posted July 2, 2024 Posted July 2, 2024 (edited) Hi All, Not sure if this is the correct area, please move to a more appropriate place if necessary. This is just a little helpful guide for anybody out there who has removed the ability for staff to create Teams and want to set an exception for a 365 security group but cannot get the GroupCreationAllowedGroupId settings value to update. https://learn.microsoft.com/en-us/microsoft-365/solutions/manage-creation-of-groups?view=o365-worldwide On the above page, Microsoft provides a Powershell script that will remove group / teams creation for your tenant and claims to allow for an exception. The script will run fine, but it will not set an exception - This is due to a filter / search function directed to the Graph modules. Search & Filter apparently are illegal / do not work with MgBetaGroup - I think it may be overlooked / changes from the straight swap from AAD The work around is to provide the Security Group's ID and update the settings value directly by doing the following: Import-Module Microsoft.Graph.Beta.Identity.DirectoryManagement Import-Module Microsoft.Graph.Beta.Groups Connect-MgGraph -Scopes "Directory.ReadWrite.All", "Group.Read.All" ##$GroupName = "Teams Creators" ----- This is the bit we're bypassing $AllowGroupCreation = "False" $settingsObjectID = (Get-MgBetaDirectorySetting | Where-object -Property Displayname -Value "Group.Unified" -EQ).id if(!$settingsObjectID) { $params = @{ templateId = "62375ab9-6b52-47ed-826b-58e47e0e304b" values = @( @{ name = "EnableMSStandardBlockedWords" value = "true" } ) } New-MgBetaDirectorySetting -BodyParameter $params $settingsObjectID = (Get-MgBetaDirectorySetting | Where-object -Property Displayname -Value "Group.Unified" -EQ).Id } ##$groupId = (Get-MgBetaGroup | Where-object {$_.displayname -eq $GroupName}).Id ---- This is the search / filter function that doesn't work!! $params = @{ templateId = "62375ab9-6b52-47ed-826b-58e47e0e304b" values = @( @{ name = "EnableGroupCreation" value = $AllowGroupCreation } @{ name = "GroupCreationAllowedGroupId" value = "INSERT THE SECURITY GROUPS ID HERE" ##Rather than search for security ID, Just provide it, it's easy enough to find in Azure. } ) } Update-MgBetaDirectorySetting -DirectorySettingId $settingsObjectID -BodyParameter $params (Get-MgBetaDirectorySetting -DirectorySettingId $settingsObjectID).Values Hope that helps somebody out there - Not much information on it online! Another quick tip is that MS365 needs group creation ENABLED for the exception group to work! - Teams creation will still be disabled for users, thanks to the script. Edited July 3, 2024 by Space_Munkey 1
ricky15100 Posted March 28, 2025 Posted March 28, 2025 Thank you so much for this, ive been banging my head against a wall trying to get this to work. Good work!!! 1
Mvandek Posted Thursday at 15:39 Posted Thursday at 15:39 (edited) Unbelievable that the Microsoft page is not corrected. I guess they want everybody to use the Sharepoint Online Management Shell for which you have to purchase Sharepoint Premium licenses. After applying this it probably takes a few hours but it than will disable the Sharepoint admin center button Build > Site with which you can create sites? Edited Thursday at 15:40 by Mvandek
Mvandek Posted Friday at 10:34 Posted Friday at 10:34 It still does not work, users can still create sites, plans, etc. Has the syntax changed again to get this working? Thanks in advance.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now